SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6174-1 | spip security update |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 22 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling. | |
| Weaknesses | CWE-688 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-22T02:24:29.207Z
Reserved: 2026-03-22T02:03:47.214Z
Link: CVE-2026-33549
No data.
Status : Received
Published: 2026-03-22T03:16:01.237
Modified: 2026-03-22T03:16:01.237
Link: CVE-2026-33549
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA